CVE-2026-32868: Opexustech Ecase Ecomplaint

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS payload in the first and last name fields. The payload is executed when the full name is rendered. The attacker can run script in the context of a victim's session.

Affected products

  • Opexustech Ecase Ecomplaint: before 10.2.0.0 (fixed in 10.2.0.0)

Published 2026-03-19. Last modified 2026-06-17.